Record summary

CVE-2018-18608 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

DedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMDedeCMS 5.7 SP2 - Cross-Site ScriptingCVSS 6.1

DedeCMS 5.7 SP2 is vulnerable to cross-site scripting via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the page numbers list at the bottom of some templates, as demonstrated by the PATH_INFO to /member/index.php, /member/pm.php, /member/content_list.php, or /plus/feedback.php.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade to the latest version of DedeCMS or apply the official patch provided by the vendor to fix the XSS vulnerability.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscve2018cvededecmsxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:dedecms:dedecms:5.7:sp2:*:*:*:*:*:*
Shodan: http.html:"DedeCms"
Shodan: cpe:"cpe:2.3:a:dedecms:dedecms"
Shodan: http.html:"dedecms"
FOFA: body="dedecms"
FOFA: app="dedecms"

Source: ProjectDiscovery

References

3